CVE-2012-3040
published 2012-10-10CVE-2012-3040: Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.56%
83.3th percentile
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_s7-1200_cpu_1211c_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1212c_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1212fc_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1214_fc_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1214c_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1215_fc_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1215c_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_cpu_1217c_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
| siemens | simatic_s7-1200_firmware | >= 2.0.0 < 3.0.2 | 3.0.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens S7-1200 Web Application Cross Site Scripting
cisa_ics·2013-08-30
Siemens S7-1200 Web Application Cross Site Scripting
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens S7-1200 Web Application Cross Site Scripting
Last RevisedAugust 30, 2013
Alert CodeICSA-12-283-01
## Overview
This advisory provides mitigation details provided by Siemens for a vulnerability that impacts the Siemens S7-1200 Web Application Module.
Siemens has reportedSSA-279823, http://www.siemens.com/corporate-technology/en/research-areas/siemens-cert-security-advisories.htm, Web site last accessed October 9, 2012. a cross-site scripting (XSS) vulnerability in Siemens’s S7-1200 Programmable Logic Controllers (PLCs). Positive TechnologiesPositive Technologies, http://p
GHSA
GHSA-53gc-p44w-x4v4: Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2
ghsa_unreviewed·2022-05-13
CVE-2012-3040 [MEDIUM] CWE-79 GHSA-53gc-p44w-x4v4: Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://en.securitylab.ru/lab/PT-2012-50http://osvdb.org/86130http://secunia.com/advisories/50816http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-279823.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-283-01.pdfhttp://en.securitylab.ru/lab/PT-2012-50http://osvdb.org/86130http://secunia.com/advisories/50816http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-279823.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-283-01.pdf
2012-10-10
Published